Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75730

5.4MEDIUM

What is CVE-2026-75730?

Adobe Experience Manager is susceptible to a stored Cross-Site Scripting (XSS) vulnerability that can be exploited by low-privileged attackers. This vulnerability allows an attacker to inject malicious scripts into specific form fields. When victims interact with a webpage containing these fields, malicious JavaScript can execute in their browsers, potentially compromising sensitive information or leading to further attacks. Proper input validation and sanitization practices are crucial to mitigate this risk.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.24

Adobe Experience Manager 6.5 LTS 0

Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.